deeptools
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is designed to assist in running NGS data analysis commands. It includes a helper script,
scripts/workflow_generator.py, which generates bash scripts containingdeepToolscommands. The script usesshlex.quotefor all interpolated variables and a strict regex filter (SAFE_PATH_PATTERN) for file paths, which effectively mitigates command injection risks from user-supplied inputs. - [DYNAMIC_EXECUTION]: The
workflow_generator.pyscript performs dynamic generation of bash script files. This implementation is safe as it uses pre-defined templates and applies comprehensive sanitization and validation (viasanitize_path,sanitize_path_list, andsanitize_positive_int) to all inputs before script creation. - [SAFE]: All identified dependencies, such as
deepTools, are standard, well-known bioinformatics packages. The skill provides legitimate utility for life sciences research without any evidence of prompt injection, unauthorized data access, or persistence mechanisms.
Audit Metadata